DIN 66399 P-Levels P-1 to P-7: How Particle Size and Maximum Area Dictate a Paper Shredder's Security
The DIN 66399 standard defines seven distinct security levels for paper shredders, relying on strict mathematical limits for particle area rather than marketing terms like 'cross-cut.' Moving from basic strip-cut to high-security micro-cut reduces a document's readable fragments by over 99 percent.
By Paige Carter
- Corporate Compliance Officers
- Focus on mitigating legal liability by ensuring data destruction meets the minimum thresholds required by privacy laws like GDPR and HIPAA.
- Hardware Manufacturers
- Balance the engineering trade-offs between high-security micro-cutting capabilities and the motor power, speed, and maintenance required to achieve them.
- Data Recovery Specialists
- Evaluate the physical limitations of optical scanning and software reconstruction against increasingly smaller paper fragments.
Perspectives this story doesn't cover
- Independent hardware repair technicians
- Municipal recycling facilities
Key terms
- DIN 66399
- The international industry standard developed by the German Institute for Standardization that defines the security levels for the destruction of various data media.
- Cross-Cut
- A shredding mechanism that cuts paper diagonally in both directions, producing small rectangular or diamond-shaped particles rather than long strips.
- Micro-Cut
- A high-security shredding mechanism (typically P-5 or higher) that reduces paper to tiny, confetti-like fragments.
- NSA/CSS 02-01
- A strict specification set by the National Security Agency requiring paper to be shredded to a maximum size of 1mm by 5mm, aligning with the DIN P-7 standard.
Key points
- The DIN 66399 standard replaced DIN 32757 in 2012, establishing seven specific security levels (P-1 to P-7) for paper destruction.
- Security levels are determined by the maximum allowable surface area and width of the shredded paper particles.
- Level P-4 (maximum 160 mm²) is the universally accepted baseline for corporate compliance with privacy laws like GDPR and HIPAA.
- Level P-7 (maximum 5 mm²) is the highest security rating, aligning with NSA requirements for top-secret intelligence destruction.
- Moving from a basic P-1 strip-cut to a P-7 micro-cut reduces the readable surface area of a single particle by 99.75 percent.
Office supply retailers routinely market any "cross-cut" shredder as a definitive solution for identity theft and corporate espionage, but the German Institute for Standardization (DIN) proves that blade style alone guarantees almost nothing. The actual security of a destroyed document is dictated entirely by the DIN 66399 standard, which measures the exact maximum area and width of the resulting paper particles. Buying a device without verifying its specific P-level rating is a gamble with sensitive data, as the physical difference between consumer-grade and compliance-grade destruction is measured in square millimeters.[1][6]
Introduced in 2012 to replace the outdated DIN 32757 standard, DIN 66399 established a universal metric for data destruction across six different media types. The "P" in the rating stands specifically for paper-based products, while other letters cover optical media, magnetic data, and electronic hard drives. For paper, the standard defines seven distinct security levels, ranging from P-1 to P-7, each enforcing a strict mathematical limit on the size of the shredded output.[1][2]
At the lowest end of the spectrum, P-1 and P-2 devices utilize a basic strip-cut mechanism. A P-1 shredder is permitted to produce strips up to 12 millimeters wide, resulting in a maximum particle area of 2,000 square millimeters. This level is intended only for general data where security is not a primary concern, effectively serving as a volume-reduction tool rather than a privacy measure.[3]
Moving up to P-2 tightens the restriction slightly, limiting the strip width to 6 millimeters and the maximum area to 800 square millimeters. While these machines process paper quickly and require less maintenance, the resulting strips run the entire length of the document. A standard A4 sheet shredded at P-2 yields roughly 35 to 40 strips, which a dedicated individual can manually reassemble in a matter of minutes.[3][5]
The critical leap in security occurs at level P-3, where the standard mandates a cross-cut mechanism that slices the paper both vertically and horizontally. A P-3 shredder must produce particles no larger than 320 square millimeters. This is the entry point for confidential documents, drastically increasing the complexity of any reconstruction effort by turning a single page into hundreds of distinct fragments rather than continuous ribbons.[3][5]
For modern corporate compliance, including the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA), P-4 is the universally recognized baseline. A P-4 device restricts the maximum particle area to 160 square millimeters, with a maximum width of 6 millimeters. This density ensures that standard font sizes are sliced multiple times, rendering individual words illegible.[5]
"Security level P-4 is the most popular security level for paper shredders," notes Recycling.com in its 2022 breakdown of the standard. At this density, a single A4 document is reduced to approximately 400 individual pieces. Reassembling a P-4 shredded document requires specialized software and optical scanning, making it economically unviable for all but the most well-funded adversaries.[3]
"Security level P-4 is the most popular security level for paper shredders," notes Recycling.com in its 2022 breakdown of the standard.
When dealing with highly sensitive or proprietary corporate data, organizations step up to P-5, commonly referred to as micro-cut. The DIN 66399 standard dictates that P-5 particles cannot exceed 30 square millimeters, with a maximum width of 2 millimeters. This level of destruction turns paper into confetti, yielding over 2,000 particles per A4 sheet.[3][4]
The utility-first trade-off with P-5 devices is speed and maintenance. Because the cutting cylinders must perform significantly more work to achieve a 30-square-millimeter particle, these shredders typically have lower sheet capacities and require frequent oiling to prevent paper jams and blade degradation. However, the security gain is substantial, effectively neutralizing software-assisted reconstruction techniques.[4][6]
Levels P-6 and P-7 enter the realm of government, military, and intelligence applications. A P-6 shredder is restricted to a maximum particle area of 10 square millimeters and a width of 1 millimeter. This is classified for highly secret data, where the threat model includes state-sponsored espionage and advanced forensic recovery laboratories.[4]
The absolute pinnacle of the DIN 66399 standard is P-7, designed for top-secret intelligence. A P-7 device must produce particles no larger than 5 square millimeters, with a maximum width of 1 millimeter. To visualize this, a single A4 sheet of paper is pulverized into more than 12,000 microscopic dust-like fragments.[4]
The P-7 standard closely aligns with the stringent requirements set by the United States government. As detailed by Security Engineered Machinery (SEM) in 2022, the NSA/CSS 02-01 specification demands that paper be reduced to dimensions that make any form of data recovery impossible. P-7 shredders achieve this, but they are expensive, slow, and can typically only process a few sheets at a time.[4]
The mathematical progression from P-1 to P-7 illustrates why the standard is so effective. Moving from a P-1 strip-cut to a P-4 cross-cut represents a 92 percent reduction in the readable surface area of a single particle. Reaching the P-7 threshold requires a staggering 99.75 percent reduction from the baseline.[6]
This exponential decrease in particle size dictates the physical engineering of the shredder. High-security devices require precision-milled solid steel cutting cylinders, robust motors capable of sustained torque, and advanced thermal management systems to handle the friction generated by micro-cutting thousands of particles per second.[1][6]
For consumers and businesses, the actionable takeaway is straightforward: ignore the marketing adjectives on the box and look directly for the DIN 66399 P-level. A home office disposing of junk mail can safely rely on a P-3 device, while any business handling customer data, financial records, or employee information must invest in a P-4 shredder at minimum to mitigate liability and ensure data destruction is mathematically guaranteed.[5][6]
Sources
[1]ProDeviceHardware ManufacturersDIN 66399 standards – What you should know!
Read on ProDevice →
[2]OntrackData Recovery SpecialistsDIN 66399 Standard for Shredder Devices & Services: Clear & Easy
Read on Ontrack →
[3]Recycling.comData Recovery SpecialistsDIN 66399 Paper Shredder Security Levels
Read on Recycling.com →
[4]SEMHardware ManufacturersShredding Security Levels
Read on SEM →
[5]Accountable HQCorporate Compliance OfficersShredding Standards Explained: DIN 66399 Security Levels and How to Choose the Right One
Read on Accountable HQ →
[6]Factlen Editorial TeamSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Shopping & Reviews
See all →Battery Tech
C-Rate vs. Amp-Hour: How Two Metrics Dictate a Battery's Maximum Power Output and Total Capacity
6 sources
Home Maintenance
MERV, HEPA, MPR, and FPR: How Four Rating Systems Dictate an Air Filter's Particle Capture and HVAC Efficiency
5 sources
Credit Card Interest
Average Daily Balance vs. Adjusted Balance: How Two Calculation Methods Dictate the Interest Charged on a Credit Card
7 sources
Shipping Logistics
UPS and FedEx Implement 25% Jump in 2026 Holiday Surcharges: How to Navigate E-Commerce Shipping Costs
4 sources
Every angle. Every day.
Get Shopping & Reviews stories with full source coverage and perspective breakdowns delivered to your inbox.




